CVE-2025-25361
06.03.2025, 19:15
An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbitrary code via uploading a crafted svg or xml file.Enginsight
Vendor | Product | Version |
---|---|---|
publiccms | publiccms | 4.0.202406.f:f |
𝑥
= Vulnerable software versions
Common Weakness Enumeration